Описание
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.15 (исключая)
cpe:2.3:a:solarwinds:managed_service_provider_patch_management_engine:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04394
Низкий
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-276
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.
EPSS
Процентиль: 89%
0.04394
Низкий
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-276